Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45502
Total
3651
Critical
13471
High
13397
Medium
CVE ID Severity Score Description Published
CVE-2026-44846 MEDIUM 6.2 JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user permission can … Aug 17, 2026
CVE-2026-44845 MEDIUM 6.7 JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management … Aug 17, 2026
CVE-2026-40506 MEDIUM 6.5 OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins … Aug 17, 2026
CVE-2026-39255 CRITICAL 9.8 Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components Aug 17, 2026
CVE-2026-39254 CRITICAL 9.8 Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components Aug 17, 2026
CVE-2026-35219 UNKNOWN Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and packages/server/src/automations/steps/discord.ts use node-fetch on user-provided URLs without the … Aug 17, 2026
CVE-2026-34789 HIGH 7.0 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML … Aug 17, 2026
CVE-2026-34399 HIGH 7.8 FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from … Aug 17, 2026
CVE-2026-34398 HIGH 7.8 FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled … Aug 17, 2026
CVE-2026-19589 HIGH 7.1 Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to … Aug 17, 2026
CVE-2026-75014 HIGH 7.3 A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the … Aug 17, 2026
CVE-2026-75013 MEDIUM 6.5 A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The … Aug 17, 2026
CVE-2026-75012 MEDIUM 6.5 A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component … Aug 17, 2026
CVE-2026-74234 HIGH 7.7 Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block … Aug 17, 2026
CVE-2026-71858 UNKNOWN Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands … Aug 17, 2026
CVE-2026-71553 UNKNOWN ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility … Aug 17, 2026
CVE-2026-71486 MEDIUM 4.3 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, … Aug 17, 2026
CVE-2026-71472 CRITICAL 9.1 A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to … Aug 17, 2026
CVE-2026-70495 HIGH 8.8 A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If … Aug 17, 2026
CVE-2026-68005 HIGH 7.5 An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in … Aug 17, 2026
CVE-2026-68004 UNKNOWN An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), … Aug 17, 2026
CVE-2026-67678 UNKNOWN File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code Aug 17, 2026
CVE-2026-63670 MEDIUM 6.1 ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included … Aug 17, 2026
CVE-2026-63669 MEDIUM 6.5 ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because … Aug 17, 2026
CVE-2026-63667 MEDIUM 6.5 ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, … Aug 17, 2026